Security issues on macOS — page 3
Issues the maintainers labelled both platform:macos and area:security.
700 issues · 147 open · 553 resolved (79%) · first seen May 17, 2025
Is this getting better or worse?
This class of problem is still growing. 265 new reports in the last 90 days vs 138 in the 90 before — +92%. The open backlog peaked at 147 in 2026-08 and sits at 147 today.
Derived by counting each matching issue from its creation date until it closed. First-party
computation over the anthropics/claude-code tracker — the trend is not published
anywhere upstream.
Which builds report this
380 of these reports name the Claude Code build they were running, spanning 132 releases. Heaviest reporters:
- Claude Code v2.1.170
- Claude Code v2.1.198
- Claude Code v2.1.212
- Claude Code v2.1.201
- Claude Code v2.1.207
- Claude Code v2.1.12
- Claude Code v2.1.202
- Claude Code v2.0.76
Report volume, not a defect count: an issue can mention a build without that build having caused the failure. Versions come from the version string in the bug-report template, matched against real published tags.
Do these get fixed?
Median time to close is 36 days across 553 closures. Of the 553 closures with a recorded reason, 23% were closed as completed and 425 as not-planned or duplicate. The most recent completed fix landed in 2026-08.
Workarounds reported by the community
129 of these issues post a workaround someone says worked. The highest-engagement ones:
- [BUG] VS CODE Extension no longer allows --dangerously-skip-permissions
- …ce with the newly updated Claude Code VSCode extension, the workaround with Ctrl+C and running 'claude --dangerously-skip-permissions' it does not work anymore. I've tried setting an alias in zshrc, but it does not work…
Found in the thread of #8539 · resolved - Skills/subagents do not inherit user-level permissions from settings.json
- …macOS 26.2 (25C56) - Settings file: ~/.claude/settings.json Workaround Select option 2 to create workspace-level permissions, but this defeats the purpose of user-level permissions. Impact Significantly degrades user exp…
Found in the description of #18950 · still open - [BUG] macOS sandbox blocks Security.framework TLS verification, breaking Go binaries (gh, terraform, etc.)
- …is script that patches the locally installed Claude Code to work around this bug: You would need to rerun this script every time Claude Code updates to re-apply the patch but it might help someone in the meantime.
Found in the thread of #23416 · still open - Skill allowed-tools doesn't grant permission for Bash commands
- …denied: The command attempted matches the pattern exactly: Workaround Adding directly to the global allow list works, but defeats the purpose of skill-scoped . Environment - Claude Code version: 2.0.75 - OS: macOS (Darw…
Found in the description of #14956 · still open - [BUG] permissions from user settings.json is NOT applied at project level
- …permissions should be a setting, not a mode. So I tried to workaround by adding permissions and it doesn't use them.
Found in the thread of #5140 · still open
Excerpts are quoted from the linked issue so you can judge relevance before opening it. Threads that only ask for a workaround, or report that there is none, are excluded. These are community suggestions, not official guidance from Anthropic — read the full thread before applying one.
Matching issues 201–300
Ranked by community engagement (reactions weighted over comments). Listing the top 300 of 700 matches; the statistics above cover all 700.
- iMessage channel sends permission relay prompts to unrelated contact
- ! shell escape prefix does not execute commands, sends as message instead
- [BUG] Write and Bash(cp) executed without permission despite restrictive settings.local.json
- [Bug] Claude Code bypassing sandbox restrictions
- [BUG] Persistent <tool_runtime_configuration> prompt injection disables Bash tool and instructs Claude to deceive user
- [Bug] Security prompt repeatedly appears despite folder being untrusted
- [FEATURE] Reduce keychain prompt friction for third-party tools (usage cache or credential export)
- [BUG] PreToolUse hooks don't block command execution in bypass mode
- [Bug] IS_DEMO=1 flag not preventing PII exposure in project context
- [BUG] I can't update my Vercel alias in Claude Code (cloud - web or app)
- [Bug] Permission bypass alias not respecting directory access in subsequent runs
- [BUG] phantom setting.json
- Claude Code decided to delete my production database
- [Bug] Anthropic API Error: Usage Policy violation on snapshot object queries
- Claude destroys production database
- [BUG] Claude Code AGGRESSIVELY reads secrets out of .env files and leaks them to your servers in so doing
- [BUG] All containers lost during port fix, Mac docker desktop
- [BUG] Failures with `SELF_SIGNED_CERT_IN_CHAIN` errors
- [Bug] PERMISSION BYPASS: lsof runs without being in allow list
- [BUG] API Error: Claude Code is unable to respond to this request, which appears to violate our Usage Policy
- [BUG] Constantly getting usage policy violations
- [Bug] Project-level Permissions Not Dynamically Updating in Active Sessions
- Anthropic API Usage Policy Violation Error Preventing Code Generation
- [BUG] Security: Project settings.json permissions.deny ignored when user's settings.json is symlinked
- Bug: Inconsistent sub-agent delegation for `/security-review` command across different projects
- [BUG] Permission Request Prompts with --dangerously-skip-permissions
- [BUG] Claude-code escaped current directory
- [BUG] The Task tool deleted a SQLite database file and replaced it with an empty directory during what should have been read-only code analysis.
- [BUG] Getting AUP violation with some requests mentioning "Zendesk"
- [BUG] Can't give permanent approval to read screenshots taken by Playwright
- [Bug] Cyber safeguard pipeline fails end-to-end in one day: 5 FP refusals on own-code defensive review, the appeal draft itself flagged, CVP denial-by-template, and 5 auto-replies (0 humans) at usersafety@
- [BUG] Cowork: update retroactively invalidated custom Cowork files root; "Change location" then copied 12.87GB incl. credentials and git repo to world-readable /Library/Application Support/Claude
- Fake <system-reminder> injected into tool output (conceal-from-user + reduced-oversight framing)
- PreToolUse hooks with Edit|Write matcher silently never invoked for an entire session (bypassPermissions, v2.1.195/196) while Bash-matched hooks fire normally
- [Bug] Security audit request flagged as inappropriate despite user ownership verification
- [Bug] Security measures triggered on legitimate system administration tasks
- [Bug] Security flag blocking legitimate infrastructure hardening operations
- [BUG] Claude Code loads fixed subset (10) of system CA certificates regardless of CLAUDE_CODE_CERT_STORE value — primary /v1/messages requests fail with UNABLE_TO_GET_ISSUER_CERT
- [BUG] Claude Code doesn't work with `NODE_OPTIONS=--use-system-ca`
- [Bug] Claude ignores user instructions to not read shell profile, exposes secrets
- [Bug] Fable 5 cybersecurity classifier false positive on legitimate infrastructure administration tasks
- [BUG] Deny List not Honored for Edit/Write
- [BUG] Can't use Claude Cowork via personal subscription on DEP enrolled Macs
- [BUG] Read of standard multer + cloudinary upload controller triggers malware system-reminder, blocking edits for session
- WebFetch summarizer fabricates <system-reminder> blocks indistinguishable from real harness reminders
- v2.1.121 VSCode native extension: permissions.deny rules not enforced
- [BUG] Stop-hook "callback" injects a synthesised user turn (isMeta:true) when a paused subagent expects SendMessage but parent has no such tool
- Auto-mode wrote a permissions allow-list entry for ssh-to-prod without per-action user approval
- [BUG] Hook stdin contains unescaped U+0000–U+001F control characters in JSON string fields, causing jq parse error and silent bypass of security hooks
- auto-mode permission-deny envelope returned without intercepting Bash dispatch (silent-bypass on git push origin main, CLI 2.1.114, Opus 4.7)
- PreToolUse hooks returning exit 2 + deny JSON do not block tool execution
- [Bug] Security: Command execution without user authorization
- Claude operated outside granted scope, modified local system without authorization
- Issue closed - please delete
- [BUG] Claudecode able to to bypass .claudeignore
- .
- [BUG] Security concern: Claude Code attempts to enumerate SSH private keys when git clone fails
- [BUG] v2.1.59: "Always allow" suggests overly broad wildcard instead of specific subcommand
- [BUG] Skill dynamic injection blocks cat for files outside session working directory
- [BUG] Stop fucking up with my git
- [BUG] Sandbox cwd tracking still causes "Exit code 1" on successful commands (regression from #11480)
- Permission allow-list captures entire literal commands instead of extracting command patterns
- [BUG] Dangerous VSCode user permisson request!!
- [Bug] Permissions configuration files not persisting across sessions
- [BUG] Claude Code prompts me to allowlist the parent directory when the current directory has spaces in it
- [BUG] Sandbox allowLocalBinding: true not applied to child/grandchild processes (breaks Gradle)
- Feature Request: Native GUI Password Prompt for Sudo Commands
- [BUG] Project-specific MCP Authentication leaks into other projects
- Internal SDK/Telemetry Code Leaking Into User Message Context
- [BUG] Chrome in Claude can bypass reCAPTCHA when user insists
- [Bug] File permission allow for Edit not working with file paths
- [BUG] Agent executed destructive `docker volume rm` without user confirmation, causing data loss
- [BUG] Hooks skipped due to workspace trust when running from home directory (~)
- Feature Request: Restore 'backup before delete' safety behavior for destructive file operations
- VSCode Extension: Permission settings (allow: [*] and defaultMode: bypassPermissions) not working
- [BUG] Workspace trust not persisting in Claude Code CLI - MCP servers fail to load despite accepting trust prompt
- [BUG] Error: Bash command permission check failed for pattern "!`bash /Users/stevenims/.claude/plugins/marketplaces/claude-code-plugins/plugins/plugin-dev/scripts/script.sh`": This command requires approval
- [BUG] Permissions: denied commands ignored with wildcard mistake
- [FEATURE] Support running claude code as a different, more restricted user
- [Bug] Security Risk: Insecure Cryptocurrency Private Key Storage Recommendation
- [BUG] Unexplained Password String Generated by Claude Code
- [BUG] I chose for Claude not to do anything and to give it new instructions and it acted like I said yes to its modifications
- Plan Mode Failure: Claude executes commands and writes files instead of creating a plan in v1.0.95
- BUG: Task Tool Agents Bypass Plan Mode Write Restrictions
- Bash:* wildcard permission not working in settings.local.json
- "Excessive Permission Prompts for Localhost API Requests in Curl Task"
- Gmail connector shown as "web" scope exposes write tools (send/reply/forward/trash) to Claude Code, and send succeeded
- permissions.deny (Bash(curl *)) silently bypassed under Auto Mode
- [BUG] Claude Code fails to authenticate on MacOS in certain environments.
- [BUG] auto mode can be remotely enabled by attacker
- Model fabricates user approval in its own turn, then executes a send tool in the same turn
- Endless SecurityAgent prompt stack for "Claude Code-credentials": credential rewrite creates keychain partition mismatch, "Always Allow" can never persist (behavior persists after #41026 was closed as resolved)
- Feature request: harness-verified lineage on inter-agent SendMessage envelopes
- [Bug] Project-scope settings.json can bypass sandbox isolation via sandbox.enabled: false
- Bash permissions.deny rules not enforced in subagent (Agent/Task tool) shells — denied command executes, only post-hoc security warning
- [MODEL] Major Data loss. Agent-constructed test payload with $(...) executed for real due to bash double-quote handling — rm -rf ~ ran against live home directory
- [Bug] Model leaks private session URL into git commits and PR bodies via Claude-Session trailer
- [Bug] Text unexpectedly converted to Korean without user action
- [Bug] Migration tool fails to preserve access control policies
- [Bug] Prompt Injection Detected in Tool Output Display Layer